chromereleases.googleblog.com
https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_0887107924.html CVE-2026-17666
CRITICAL
Google Chrome Enterprise Cryptographic Flaw Allowing Discretionary Access Control Bypass
Record summary
CVE-2026-17666 has a selected CVSS score of 9.1 (critical).
Description
Cryptographic Flaw in Enterprise in Google Chrome prior to 151.0.7922.72 allowed an attacker in a privileged network position to bypass discretionary access control via malicious network traffic. (Chromium security severity: High)
Description source: CVE List
Exploitation context
CISA SSVC decision
ExploitationNone
AutomatableYes
Technical impactTotal
CISA Coordinator · SSVC 2.0.3 · Evaluated Jul 30, 2026 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
ChromeBrowse Google / Chrome | CVE List | 151.0.7922.72 to < 151.0.7922.72 | affected |
References
3issues.chromium.org
https://issues.chromium.org/issues/511761758 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2026-17666